...
These symptoms are observed on affected versions of the Firepower Management Center (FMC): - On the FMC user interface on the Smart Licenses page the "Failed to send the message to the server. Please verify the DNS Server/HTTP Proxy settings." message is shown. - In /var/log/httpd/httpsd_error_log a message that contains this line: 'Smart Agent communication error with Smart Licensing Cloud': /usr/local/sf/htdocs/events/index.cgi - In /var/log/process_stdout.log* a message that contains this line: ch_pf_curl_send_msg[526], failed to perform, err code 60, err string "SSL peer certificate or SSH remote key was not OK" - In /var/log/action_queue.log* a message that contains this line: Registration to the Cisco Smart Software Manager || Failed to register
Software versions earlier than Fixed Version of the table with the title "Firepower - Software Upgrade" in the Field Notice (FN) https://www.cisco.com/c/en/us/support/docs/field-notices/721/fn72103.html
It is strongly recommended to move to a fixed version. Review the Field Notice below: https://www.cisco.com/c/en/us/support/docs/field-notices/721/fn72103.html ----------------------------------------------------------- WORKAROUND STEPS FOR AFFECTED VERSION: ----------------------------------------------------------- 1. Copy-paste the below content at the end of the file named: /etc/sf/gch/call_home_ca -----BEGIN CERTIFICATE----- MIIFYDCCA0igAwIBAgIQCgFCgAAAAUUjyES1AAAAAjANBgkqhkiG9w0BAQsFADBK MQswCQYDVQQGEwJVUzESMBAGA1UEChMJSWRlblRydXN0MScwJQYDVQQDEx5JZGVu VHJ1c3QgQ29tbWVyY2lhbCBSb290IENBIDEwHhcNMTQwMTE2MTgxMjIzWhcNMzQw MTE2MTgxMjIzWjBKMQswCQYDVQQGEwJVUzESMBAGA1UEChMJSWRlblRydXN0MScw JQYDVQQDEx5JZGVuVHJ1c3QgQ29tbWVyY2lhbCBSb290IENBIDEwggIiMA0GCSqG SIb3DQEBAQUAA4ICDwAwggIKAoICAQCnUBneP5k91DNG8W9RYYKyqU+PZ4ldhNlT 3Qwo2dfw/66VQ3KZ+bVdfIrBQuExUHTRgQ18zZshq0PirK1ehm7zCYofWjK9ouuU +ehcCuz/mNKvcbO0U59Oh++SvL3sTzIwiEsXXlfEU8L2ApeN2WIrvyQfYo3fw7gp S0l4PJNgiCL8mdo2yMKi1CxUAGc1bnO/AljwpN3lsKImesrgNqUZFvX9t++uP0D1 bVoE/c40yiTcdCMbXTMTEl3EASX2MN0CXZ/g1Ue9tOsbobtJSdifWwLziuQkkORi T0/Br4sOdBeo0XKIanoBScy0RnnGF7HamB4HWfp1IYVl3ZBWzvurpWCdxJ35UrCL vYf5jysjCiN2O/cz4ckA82n5S6LgTrx+kzmEB/dEcH7+B1rlsazRGMzyNeVJSQjK Vsk9+w8YfYs7wRPCTY/JTw436R+hDmrfYi7LNQZReSzIJTj0+kuniVyc0uMNOYZK dHzVWYfCP04MXFL0PfdSgvHqo6z9STQaKPNBiDoT7uje/5kdX7rL6B7yuVBgwDHT c+XvvqDtMwt0viAgxGds8AgDelWAf0ZOlqf0Hj7h9tgJ4TNkK2PXMl6f+cB7D3hv l7yTmvmcEpB4eoCHFddydJxVdHixuuFucAS6T6C6aMN7/zHwcz09lCqxC0EOoP5N iGVreTO01wIDAQABo0IwQDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB /zAdBgNVHQ4EFgQU7UQZwNPwBovupHu+QucmVMiONnYwDQYJKoZIhvcNAQELBQAD ggIBAA2ukDL2pkt8RHYZYR4nKM1eVO8lvOMIkPkp165oCOGUAFjvLi5+U1KMtlwH 6oi6mYtQlNeCgN9hCQCTrQ0U5s7B8jeUeLBfnLOic7iPBZM4zY0+sLj7wM+x8uwt LRvM7Kqas6pgghstO8OEPVeKlh6cdbjTMM1gCIOQ045U8U1mwF10A0Cj7oV+wh93 nAbowacYXVKV7cndJZ5t+qntozo00Fl72u1Q8zW/7esUTTHHYPTa8Yec4kjixsU3 +wYQ+nVZZjFHKdp2mhzpgq7vmrlR94gjmmmVYjzlVYA211QC//G5Xc7UI2/YRYRK W2XviQzdFKcgyxilJbQN+QHwotL0AMh0jqEqSI5l2xPE4iUXfeu+h1sXIFRRk0pT AwvsXcoz7WL9RccvW9xYoIA55vrX/hMUpu09lEpCdNTDd1lzzY9GvlU47/rokTLq l1gEIt44w8y8bckzOmoKaT+gyOpyj4xjhiO9bTyWnpXgSUyqorkqG5w2gXjtw+hG 4iZZRHUe2XWJUc0QhJ1hYMtd+ZciTY6Y5uN/9lu7rs3KSoFrXgvzUeF0K+l+J6fZ mUlO+KWA2yUPHGNiiskzZ2s8EIPGrd6ozRaOjfAHN3Gf8qv8QfXBi+wAN10J5U6A 7/qxXDgGpRtK4dw4LTzcqx+QGtVKnO7RcGzM7vRX+Bi6hG6H -----END CERTIFICATE----- - Special characters may exist at the end of the file that needs to be removed: e.g. ^@ 2. Restart SLA by running the below command as the root user: # pmtool restartbyid sla ------------------------------------------------------------ WORKAROUND STEPS FOR FIXED VERSION: ------------------------------------------------------------ After FMC upgrade to a fixed version, the user must remove the certificate file at /etc/sf/gch/call_home_ca and restart the Smart Licensing Agent (sla) process to resume communications with Cisco Smart Software Manager (CSSM) with these steps: 1. Access the CLI. For FMC deployments, log in to the FMC CLI as admin or another user with shell access. 2. Enter the expert command in order to access the Linux shell. 3. Elevate the user to root with the "sudo su" command and enter the password when prompted. 4. Remove the /etc/sf/gch/call_home_ca file with the rm /etc/sf/gch/call_home_ca command. 5. Restart the Smart Licensing Agreement process with the "pmtool restartbyid sla" command. ---------------------------
For more information refer to the Field Notice: FN - 72103 - ASA and Firepower Software - QuoVadis Root Certificate Decommission Might Affect Smart Licensing, Smart Call Home, And Other Functionality - Software Upgrade Recommended https://www.cisco.com/c/en/us/support/docs/field-notices/721/fn72103.html